OliverDB Cloud — Data Processing Addendum

Effective date: August 25, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Oliver AI, Inc. ("Processor," "we") and Customer ("Controller," "you") and applies to the extent we process personal data contained in Customer Content on your behalf subject to Applicable Data Protection Law (including, where applicable, the GDPR, UK GDPR, and US state privacy laws).

1. Roles and Scope

You are the controller (or a processor acting for another controller) of personal data in Customer Content; we are your processor. We process such data only on your documented instructions — which are: to provide, secure, and support the Service as described in the Terms and your configuration of it — unless processing is required by law, in which case we will inform you unless legally prohibited.

Details of processing. Subject matter & duration: provision of the Service for the term of the agreement. Nature & purpose: hosting, storage, ingestion, querying, transmission, and deletion of Customer Content. Categories of data and data subjects: determined and controlled by you; the Service is schema-agnostic and typically processes machine and application telemetry. Special categories: not permitted without written agreement (see Terms §4).

2. Confidentiality

We ensure persons authorized to process Customer Content are bound by confidentiality obligations and access it only as needed to provide the Service.

3. Security

We implement appropriate technical and organizational measures, including those in Annex A. We may update them, provided the protection level does not materially decrease.

4. Subprocessors

You provide general authorization for the subprocessors listed at our Subprocessor List at https://oliverdb.ai/legal/subprocessors. We will give at least 30 days' notice (via the console or the list page's change log) before adding or replacing a subprocessor; you may object on reasonable data-protection grounds, and if we cannot accommodate the objection you may terminate the affected service with a pro-rata refund of prepaid, unused fees. We impose data-protection obligations on subprocessors no less protective than this DPA and remain liable for their performance.

5. Assistance

Taking into account the nature of processing, we will reasonably assist you with: responding to data-subject requests (the Service's query and deletion capabilities are the primary mechanism; we assist where those are insufficient); security of processing; breach notifications; and data-protection impact assessments, at your reasonable expense where material effort is required.

6. Personal Data Breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Content, and in any case within 72 hours, providing information reasonably available to us to support your own notification obligations, supplemented as investigation proceeds.

7. Deletion and Return

You can export and delete Customer Content at any time through the Service. On termination, the Terms' export window applies, after which we delete Customer Content (including backups on their scheduled rotation) unless retention is required by law. On request we will confirm deletion in writing.

8. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable security questionnaires and summaries of third-party assessments when available. Where Applicable Data Protection Law grants you an audit right that cannot be satisfied this way, an audit may be conducted at most annually, on 30 days' notice, during business hours, without access to other customers' data, at your expense.

9. International Transfers

Where transfers of EEA/UK personal data to us require a transfer mechanism, the EU Standard Contractual Clauses (Module 2, Controller-to-Processor) and, for the UK, the ICO Addendum, are incorporated by reference, with: you as data exporter; us as data importer; the processing details in Section 1; the measures in Annex A; and the subprocessor list in Section 4. In case of conflict, the Clauses prevail.

10. Liability & Order of Precedence

Liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms regarding personal-data processing, this DPA prevails.


Annex A — Technical and Organizational Measures

← oliverdb.ai console · Terms · Privacy · AUP · DPA · Subprocessors